Session Fixation in snipe/snipe-it

Valid

Reported on

Aug 22nd 2022


Description

The session is not invalidated after a password change.

Proof of Concept

Open Snipe-IT in the browser and login. Do the same in a private window such that there are two sessions. Change the password in one of the two sessions and observe that the second session is not invalidated.

Impact

An old session can be used even after the password has been changed.

We are processing your report and will contact the snipe/snipe-it team within 24 hours. a year ago
We have contacted a member of the snipe/snipe-it team and are waiting to hear back a year ago
snipe validated this vulnerability a year ago
vautia has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
snipe marked this as fixed in 6.0.10 with commit 6fde72 a year ago
snipe has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation